PAN-SA-2025-0005: GlobalProtect Clientless VPN: Clientless VPN Misconfiguration Allows Cross-Site Attacks
Palo Alto Networks GlobalProtect Clientless VPN is intended to provide secure remote access to trusted internal applications. It is not meant to provide access to the Internet, intranet or multiple websites.
When the Clientless VPN is misconfigured to allow access to the Internet or any internal website, it allows malicious scripts on one site to obtain sensitive information or modify content of any application accessible through the VPN including Clientless VPN itself.
For further details about the risks of Clientless VPNs please refer to https://www.kb.cert.org/vuls/id/261869
Affected Software
Remediation
Mitigation
Event History
Frequently Asked Questions
What is the severity of PAN-SA-2025-0005?
The severity of PAN-SA-2025-0005 is considered high due to the potential for unauthorized access to the Internet.
How do I fix PAN-SA-2025-0005?
To fix PAN-SA-2025-0005, ensure that the GlobalProtect Clientless VPN is properly configured to limit access only to trusted internal applications.
What products are affected by PAN-SA-2025-0005?
PAN-SA-2025-0005 affects Palo Alto Networks Cloud NGFW, PAN-OS, and Prisma Access.
What vulnerability does PAN-SA-2025-0005 address?
PAN-SA-2025-0005 addresses a misconfiguration issue that may allow unauthorized Internet access through the Clientless VPN.
Is there a workaround for PAN-SA-2025-0005?
A workaround for PAN-SA-2025-0005 is to restrict access to the Clientless VPN settings to prevent Internet access.